xref: /openbsd-src/sys/kern/exec_subr.c (revision b2c8260306ba9e39e6b861d0017b65cea1140e0b)
1*b2c82603Sjsg /*	$OpenBSD: exec_subr.c,v 1.68 2024/11/02 10:02:23 jsg Exp $	*/
2df930be7Sderaadt /*	$NetBSD: exec_subr.c,v 1.9 1994/12/04 03:10:42 mycroft Exp $	*/
3df930be7Sderaadt 
4df930be7Sderaadt /*
5df930be7Sderaadt  * Copyright (c) 1993, 1994 Christopher G. Demetriou
6df930be7Sderaadt  * All rights reserved.
7df930be7Sderaadt  *
8df930be7Sderaadt  * Redistribution and use in source and binary forms, with or without
9df930be7Sderaadt  * modification, are permitted provided that the following conditions
10df930be7Sderaadt  * are met:
11df930be7Sderaadt  * 1. Redistributions of source code must retain the above copyright
12df930be7Sderaadt  *    notice, this list of conditions and the following disclaimer.
13df930be7Sderaadt  * 2. Redistributions in binary form must reproduce the above copyright
14df930be7Sderaadt  *    notice, this list of conditions and the following disclaimer in the
15df930be7Sderaadt  *    documentation and/or other materials provided with the distribution.
16df930be7Sderaadt  * 3. All advertising materials mentioning features or use of this software
17df930be7Sderaadt  *    must display the following acknowledgement:
18df930be7Sderaadt  *      This product includes software developed by Christopher G. Demetriou.
19df930be7Sderaadt  * 4. The name of the author may not be used to endorse or promote products
20df930be7Sderaadt  *    derived from this software without specific prior written permission
21df930be7Sderaadt  *
22df930be7Sderaadt  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
23df930be7Sderaadt  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
24df930be7Sderaadt  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
25df930be7Sderaadt  * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
26df930be7Sderaadt  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
27df930be7Sderaadt  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
28df930be7Sderaadt  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
29df930be7Sderaadt  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
30df930be7Sderaadt  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
31df930be7Sderaadt  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
32df930be7Sderaadt  */
33df930be7Sderaadt 
34df930be7Sderaadt #include <sys/param.h>
35df930be7Sderaadt #include <sys/systm.h>
36df930be7Sderaadt #include <sys/proc.h>
37df930be7Sderaadt #include <sys/malloc.h>
38df930be7Sderaadt #include <sys/vnode.h>
39df930be7Sderaadt #include <sys/exec.h>
40df930be7Sderaadt #include <sys/mman.h>
41a398dccbSderaadt #include <sys/resourcevar.h>
42df930be7Sderaadt 
43fde894e5Stedu #include <uvm/uvm_extern.h>
44fde894e5Stedu 
45df930be7Sderaadt /*
46df930be7Sderaadt  * new_vmcmd():
47df930be7Sderaadt  *	create a new vmcmd structure and fill in its fields based
48df930be7Sderaadt  *	on function call arguments.  make sure objects ref'd by
49df930be7Sderaadt  *	the vmcmd are 'held'.
50df930be7Sderaadt  */
51df930be7Sderaadt 
52df930be7Sderaadt void
5348bd9750Stedu new_vmcmd(struct exec_vmcmd_set *evsp,
5448bd9750Stedu     int (*proc)(struct proc *, struct exec_vmcmd *), u_long len, u_long addr,
5548bd9750Stedu     struct vnode *vp, u_long offset, u_int prot, int flags)
56df930be7Sderaadt {
57df930be7Sderaadt 	struct exec_vmcmd    *vcp;
58df930be7Sderaadt 
59df930be7Sderaadt 	if (evsp->evs_used >= evsp->evs_cnt)
60df930be7Sderaadt 		vmcmdset_extend(evsp);
61df930be7Sderaadt 	vcp = &evsp->evs_cmds[evsp->evs_used++];
62df930be7Sderaadt 	vcp->ev_proc = proc;
63df930be7Sderaadt 	vcp->ev_len = len;
64df930be7Sderaadt 	vcp->ev_addr = addr;
65df930be7Sderaadt 	if ((vcp->ev_vp = vp) != NULL)
66df930be7Sderaadt 		vref(vp);
67df930be7Sderaadt 	vcp->ev_offset = offset;
68df930be7Sderaadt 	vcp->ev_prot = prot;
6971904debSmickey 	vcp->ev_flags = flags;
70df930be7Sderaadt }
71df930be7Sderaadt 
72df930be7Sderaadt void
7348bd9750Stedu vmcmdset_extend(struct exec_vmcmd_set *evsp)
74df930be7Sderaadt {
75df930be7Sderaadt 	struct exec_vmcmd *nvcp;
76df930be7Sderaadt 	u_int ocnt;
77df930be7Sderaadt 
78df930be7Sderaadt #ifdef DIAGNOSTIC
79df930be7Sderaadt 	if (evsp->evs_used < evsp->evs_cnt)
80df930be7Sderaadt 		panic("vmcmdset_extend: not necessary");
81df930be7Sderaadt #endif
82df930be7Sderaadt 
83df930be7Sderaadt 	ocnt = evsp->evs_cnt;
848a5bc863Sart 	KASSERT(ocnt > 0);
858a5bc863Sart 	/* figure out number of entries in new set */
868a5bc863Sart 	evsp->evs_cnt += ocnt;
87df930be7Sderaadt 
888a5bc863Sart 	/* reallocate the command set */
89a11de6bdStedu 	nvcp = mallocarray(evsp->evs_cnt, sizeof(*nvcp), M_EXEC,
90176819c2Sart 	    M_WAITOK);
912955d5bcStedu 	memcpy(nvcp, evsp->evs_cmds, ocnt * sizeof(*nvcp));
928a5bc863Sart 	if (evsp->evs_cmds != evsp->evs_start)
93a11de6bdStedu 		free(evsp->evs_cmds, M_EXEC, ocnt * sizeof(*nvcp));
94df930be7Sderaadt 	evsp->evs_cmds = nvcp;
95df930be7Sderaadt }
96df930be7Sderaadt 
97df930be7Sderaadt void
981e04e351Sart kill_vmcmds(struct exec_vmcmd_set *evsp)
99df930be7Sderaadt {
100df930be7Sderaadt 	struct exec_vmcmd *vcp;
101df930be7Sderaadt 	int i;
102df930be7Sderaadt 
103df930be7Sderaadt 	for (i = 0; i < evsp->evs_used; i++) {
104df930be7Sderaadt 		vcp = &evsp->evs_cmds[i];
105df930be7Sderaadt 		if (vcp->ev_vp != NULLVP)
106df930be7Sderaadt 			vrele(vcp->ev_vp);
107df930be7Sderaadt 	}
1088a5bc863Sart 
1098a5bc863Sart 	/*
11078cbf1bdShshoexer 	 * Free old vmcmds and reset the array.
1118a5bc863Sart 	 */
1128a5bc863Sart 	evsp->evs_used = 0;
1138a5bc863Sart 	if (evsp->evs_cmds != evsp->evs_start)
114c4deb1d2Sderaadt 		free(evsp->evs_cmds, M_EXEC,
115c4deb1d2Sderaadt 		    evsp->evs_cnt * sizeof(struct exec_vmcmd));
1168a5bc863Sart 	evsp->evs_cmds = evsp->evs_start;
1178a5bc863Sart 	evsp->evs_cnt = EXEC_DEFAULT_VMCMD_SETSIZE;
118df930be7Sderaadt }
119df930be7Sderaadt 
1201e04e351Sart int
1211e04e351Sart exec_process_vmcmds(struct proc *p, struct exec_package *epp)
1221e04e351Sart {
1231e04e351Sart 	struct exec_vmcmd *base_vc = NULL;
1241e04e351Sart 	int error = 0;
1251e04e351Sart 	int i;
1261e04e351Sart 
1271e04e351Sart 	for (i = 0; i < epp->ep_vmcmds.evs_used && !error; i++) {
1281e04e351Sart 		struct exec_vmcmd *vcp;
1291e04e351Sart 
1301e04e351Sart 		vcp = &epp->ep_vmcmds.evs_cmds[i];
1311e04e351Sart 
1321e04e351Sart 		if (vcp->ev_flags & VMCMD_RELATIVE) {
1331e04e351Sart #ifdef DIAGNOSTIC
1341e04e351Sart 			if (base_vc == NULL)
1351e04e351Sart 				panic("exec_process_vmcmds: RELATIVE no base");
1361e04e351Sart #endif
1371e04e351Sart 			vcp->ev_addr += base_vc->ev_addr;
1381e04e351Sart 		}
1391e04e351Sart 		error = (*vcp->ev_proc)(p, vcp);
1401e04e351Sart 		if (vcp->ev_flags & VMCMD_BASE) {
1411e04e351Sart 			base_vc = vcp;
1421e04e351Sart 		}
1431e04e351Sart 	}
1441e04e351Sart 
1451e04e351Sart 	kill_vmcmds(&epp->ep_vmcmds);
1461e04e351Sart 
1471e04e351Sart 	return (error);
1481e04e351Sart }
1491e04e351Sart 
150df930be7Sderaadt /*
151df930be7Sderaadt  * vmcmd_map_pagedvn():
152df930be7Sderaadt  *	handle vmcmd which specifies that a vnode should be mmap'd.
153df930be7Sderaadt  *	appropriate for handling demand-paged text and data segments.
154df930be7Sderaadt  */
155df930be7Sderaadt 
156df930be7Sderaadt int
15748bd9750Stedu vmcmd_map_pagedvn(struct proc *p, struct exec_vmcmd *cmd)
158df930be7Sderaadt {
1591414b0faSart 	/*
160d8a79e40Sjmc 	 * note that if you're going to map part of a process as being
1611414b0faSart 	 * paged from a vnode, that vnode had damn well better be marked as
1621414b0faSart 	 * VTEXT.  that's handled in the routine which sets up the vmcmd to
1631414b0faSart 	 * call this routine.
1641414b0faSart 	 */
165837b04fdSart 	struct uvm_object *uobj;
16631b48a6bSderaadt 	unsigned int flags = UVM_FLAG_COPYONW | UVM_FLAG_FIXED;
167cf0f9f55Sart 	int error;
168837b04fdSart 
169837b04fdSart 	/*
170837b04fdSart 	 * map the vnode in using uvm_map.
171837b04fdSart 	 */
172837b04fdSart 
173837b04fdSart 	if (cmd->ev_len == 0)
174837b04fdSart 		return (0);
175837b04fdSart 	if (cmd->ev_offset & PAGE_MASK)
176837b04fdSart 		return (EINVAL);
177837b04fdSart 	if (cmd->ev_addr & PAGE_MASK)
178837b04fdSart 		return (EINVAL);
17941769dfbSart 	if (cmd->ev_len & PAGE_MASK)
18041769dfbSart 		return (EINVAL);
181837b04fdSart 
182837b04fdSart 	/*
183837b04fdSart 	 * first, attach to the object
184837b04fdSart 	 */
185837b04fdSart 
1861e8cdc2eSderaadt 	uobj = uvn_attach(cmd->ev_vp, PROT_READ | PROT_EXEC);
187837b04fdSart 	if (uobj == NULL)
188837b04fdSart 		return (ENOMEM);
189837b04fdSart 
190837b04fdSart 	/*
191837b04fdSart 	 * do the map
192837b04fdSart 	 */
193cf0f9f55Sart 	error = uvm_map(&p->p_vmspace->vm_map, &cmd->ev_addr, cmd->ev_len,
194198a4b3fSart 	    uobj, cmd->ev_offset, 0,
195e087cc70Sguenther 	    UVM_MAPFLAG(cmd->ev_prot, PROT_MASK, MAP_INHERIT_COPY,
19631b48a6bSderaadt 	    MADV_NORMAL, flags));
197837b04fdSart 
1981414b0faSart 	/*
1991414b0faSart 	 * check for error
2001414b0faSart 	 */
201738a5b4dSart 
202cf0f9f55Sart 	if (error) {
2031414b0faSart 		/*
2041414b0faSart 		 * error: detach from object
2051414b0faSart 		 */
2061414b0faSart 		uobj->pgops->pgo_detach(uobj);
20731b48a6bSderaadt 	} else {
20831b48a6bSderaadt 		if (cmd->ev_flags & VMCMD_IMMUTABLE)
2093d4f5926Sderaadt 			uvm_map_immutable(&p->p_vmspace->vm_map, cmd->ev_addr,
2103d4f5926Sderaadt 			    round_page(cmd->ev_addr + cmd->ev_len), 1);
211d62ebcb2Sderaadt #ifdef PMAP_CHECK_COPYIN
212d62ebcb2Sderaadt 		if (PMAP_CHECK_COPYIN &&
21330d20579Sderaadt 		    ((cmd->ev_flags & VMCMD_IMMUTABLE) && (cmd->ev_prot & PROT_EXEC)))
214d62ebcb2Sderaadt 			uvm_map_check_copyin_add(&p->p_vmspace->vm_map,
215d62ebcb2Sderaadt 			    cmd->ev_addr, round_page(cmd->ev_addr + cmd->ev_len));
216d62ebcb2Sderaadt #endif
217cf0f9f55Sart 	}
218cf0f9f55Sart 
219cf0f9f55Sart 	return (error);
220df930be7Sderaadt }
221df930be7Sderaadt 
222df930be7Sderaadt /*
223df930be7Sderaadt  * vmcmd_map_readvn():
224df930be7Sderaadt  *	handle vmcmd which specifies that a vnode should be read from.
225df930be7Sderaadt  *	appropriate for non-demand-paged text/data segments, i.e. impure
226df930be7Sderaadt  *	objects (a la OMAGIC and NMAGIC).
227df930be7Sderaadt  */
2283dad825aSart 
229df930be7Sderaadt int
2303dad825aSart vmcmd_map_readvn(struct proc *p, struct exec_vmcmd *cmd)
231df930be7Sderaadt {
232df930be7Sderaadt 	int error;
2333dad825aSart 	vm_prot_t prot;
234df930be7Sderaadt 
235837b04fdSart 	if (cmd->ev_len == 0)
236738a5b4dSart 		return (0);
237837b04fdSart 
2383dad825aSart 	prot = cmd->ev_prot;
2393dad825aSart 
24031b48a6bSderaadt 	KASSERT((cmd->ev_addr & PAGE_MASK) == 0);
241837b04fdSart 	error = uvm_map(&p->p_vmspace->vm_map, &cmd->ev_addr,
242198a4b3fSart 	    round_page(cmd->ev_len), NULL, UVM_UNKNOWN_OFFSET, 0,
243e087cc70Sguenther 	    UVM_MAPFLAG(prot | PROT_WRITE, PROT_MASK, MAP_INHERIT_COPY,
24415cd8707Sguenther 	    MADV_NORMAL, UVM_FLAG_FIXED|UVM_FLAG_OVERLAY|UVM_FLAG_COPYONW));
245837b04fdSart 
246df930be7Sderaadt 	if (error)
247738a5b4dSart 		return (error);
248df930be7Sderaadt 
249df930be7Sderaadt 	error = vn_rdwr(UIO_READ, cmd->ev_vp, (caddr_t)cmd->ev_addr,
25064a23ac2Ssturm 	    cmd->ev_len, cmd->ev_offset, UIO_USERSPACE, IO_UNIT,
2519b355cb2Smillert 	    p->p_ucred, NULL, p);
252df930be7Sderaadt 	if (error)
253738a5b4dSart 		return (error);
254df930be7Sderaadt 
2551e8cdc2eSderaadt 	if ((prot & PROT_WRITE) == 0) {
256837b04fdSart 		/*
257fd6bec85Sguenther 		 * we had to map in the area at PROT_WRITE so that vn_rdwr()
258837b04fdSart 		 * could write to it.   however, the caller seems to want
259837b04fdSart 		 * it mapped read-only, so now we are going to have to call
260837b04fdSart 		 * uvm_map_protect() to fix up the protection.  ICK.
261837b04fdSart 		 */
26231b48a6bSderaadt 		error = (uvm_map_protect(&p->p_vmspace->vm_map,
26331b48a6bSderaadt 		    cmd->ev_addr, round_page(cmd->ev_len),
2644c8ae43bSderaadt 		    prot, 0, FALSE, TRUE));
265837b04fdSart 	}
26631b48a6bSderaadt 	if (error == 0) {
2673d4f5926Sderaadt 		if (cmd->ev_flags & VMCMD_IMMUTABLE)
2683d4f5926Sderaadt 			uvm_map_immutable(&p->p_vmspace->vm_map, cmd->ev_addr,
2693d4f5926Sderaadt 			    round_page(cmd->ev_addr + cmd->ev_len), 1);
27031b48a6bSderaadt 	}
27131b48a6bSderaadt 	return (error);
272df930be7Sderaadt }
273df930be7Sderaadt 
274df930be7Sderaadt /*
275df930be7Sderaadt  * vmcmd_map_zero():
276ed5f6befSguenther  *	handle vmcmd which specifies a zero-filled address space region.
277df930be7Sderaadt  */
278df930be7Sderaadt 
279df930be7Sderaadt int
28048bd9750Stedu vmcmd_map_zero(struct proc *p, struct exec_vmcmd *cmd)
281df930be7Sderaadt {
28231b48a6bSderaadt 	int error;
28331b48a6bSderaadt 
284837b04fdSart 	if (cmd->ev_len == 0)
285738a5b4dSart 		return (0);
286837b04fdSart 
28731b48a6bSderaadt 	KASSERT((cmd->ev_addr & PAGE_MASK) == 0);
28831b48a6bSderaadt 	error = uvm_map(&p->p_vmspace->vm_map, &cmd->ev_addr,
289198a4b3fSart 	    round_page(cmd->ev_len), NULL, UVM_UNKNOWN_OFFSET, 0,
290e087cc70Sguenther 	    UVM_MAPFLAG(cmd->ev_prot, PROT_MASK, MAP_INHERIT_COPY,
291003f5e42Sderaadt 	    MADV_NORMAL, UVM_FLAG_FIXED|UVM_FLAG_COPYONW |
29231b48a6bSderaadt 	    (cmd->ev_flags & VMCMD_STACK ? UVM_FLAG_STACK : 0)));
2933d4f5926Sderaadt 	if (cmd->ev_flags & VMCMD_IMMUTABLE)
2943d4f5926Sderaadt 		uvm_map_immutable(&p->p_vmspace->vm_map, cmd->ev_addr,
2953d4f5926Sderaadt 		    round_page(cmd->ev_addr + cmd->ev_len), 1);
29631b48a6bSderaadt 	return error;
29731b48a6bSderaadt }
29831b48a6bSderaadt 
29931b48a6bSderaadt /*
30031b48a6bSderaadt  * vmcmd_mutable():
30131b48a6bSderaadt  *	handle vmcmd which changes an address space region.back to mutable
30231b48a6bSderaadt  */
30331b48a6bSderaadt 
30431b48a6bSderaadt int
30531b48a6bSderaadt vmcmd_mutable(struct proc *p, struct exec_vmcmd *cmd)
30631b48a6bSderaadt {
30731b48a6bSderaadt 	if (cmd->ev_len == 0)
30831b48a6bSderaadt 		return (0);
30931b48a6bSderaadt 
31031b48a6bSderaadt 	/* ev_addr, ev_len may be misaligned, so maximize the region */
31131b48a6bSderaadt 	uvm_map_immutable(&p->p_vmspace->vm_map, trunc_page(cmd->ev_addr),
3121c71e4e1Sderaadt 	    round_page(cmd->ev_addr + cmd->ev_len), 0);
31331b48a6bSderaadt 	return 0;
314df930be7Sderaadt }
315a398dccbSderaadt 
316a398dccbSderaadt /*
3175f706690Smatthew  * vmcmd_randomize():
3185f706690Smatthew  *	handle vmcmd which specifies a randomized address space region.
3195f706690Smatthew  */
3206d1ec4b9Smortimer #define RANDOMIZE_CTX_THRESHOLD 512
3215f706690Smatthew int
3225f706690Smatthew vmcmd_randomize(struct proc *p, struct exec_vmcmd *cmd)
3235f706690Smatthew {
3245f706690Smatthew 	int error;
3256d1ec4b9Smortimer 	struct arc4random_ctx *ctx;
3266d1ec4b9Smortimer 	char *buf;
327a4349a2eSmortimer 	size_t sublen, off = 0;
3286d1ec4b9Smortimer 	size_t len = cmd->ev_len;
3295f706690Smatthew 
3306d1ec4b9Smortimer 	if (len == 0)
3315f706690Smatthew 		return (0);
3326d1ec4b9Smortimer 	if (len > ELF_RANDOMIZE_LIMIT)
3335f706690Smatthew 		return (EINVAL);
3345f706690Smatthew 
3351a0bd10fSderaadt 	buf = malloc(PAGE_SIZE, M_TEMP, M_WAITOK);
3366d1ec4b9Smortimer 	if (len < RANDOMIZE_CTX_THRESHOLD) {
3376d1ec4b9Smortimer 		arc4random_buf(buf, len);
3386d1ec4b9Smortimer 		error = copyout(buf, (void *)cmd->ev_addr, len);
3396d1ec4b9Smortimer 		explicit_bzero(buf, len);
3406d1ec4b9Smortimer 	} else {
3416d1ec4b9Smortimer 		ctx = arc4random_ctx_new();
3421a0bd10fSderaadt 		do {
3436d1ec4b9Smortimer 			sublen = MIN(len, PAGE_SIZE);
3446d1ec4b9Smortimer 			arc4random_ctx_buf(ctx, buf, sublen);
3451a0bd10fSderaadt 			error = copyout(buf, (void *)cmd->ev_addr + off, sublen);
3461a0bd10fSderaadt 			if (error)
3471a0bd10fSderaadt 				break;
3481a0bd10fSderaadt 			off += sublen;
3491a0bd10fSderaadt 			len -= sublen;
350a4349a2eSmortimer 			sched_pause(yield);
3511a0bd10fSderaadt 		} while (len);
3526d1ec4b9Smortimer 		arc4random_ctx_free(ctx);
3536d1ec4b9Smortimer 		explicit_bzero(buf, PAGE_SIZE);
3546d1ec4b9Smortimer 	}
3551a0bd10fSderaadt 	free(buf, M_TEMP, PAGE_SIZE);
3565f706690Smatthew 	return (error);
3575f706690Smatthew }
3585f706690Smatthew 
3594ed6bfeaSkettenis #ifndef MAXSSIZ_GUARD
3604ed6bfeaSkettenis #define MAXSSIZ_GUARD	(1024 * 1024)
3614ed6bfeaSkettenis #endif
3624ed6bfeaSkettenis 
3635f706690Smatthew /*
364729747ffSderaadt  * exec_setup_stack(): Set up the stack segment for an executable.
365a398dccbSderaadt  *
366a398dccbSderaadt  * Note that the ep_ssize parameter must be set to be the current stack
367a398dccbSderaadt  * limit; this is adjusted in the body of execve() to yield the
368a398dccbSderaadt  * appropriate stack segment usage once the argument length is
369a398dccbSderaadt  * calculated.
370a398dccbSderaadt  *
371a398dccbSderaadt  * This function returns an int for uniformity with other (future) formats'
372a398dccbSderaadt  * stack setup functions.  They might have errors to return.
373a398dccbSderaadt  */
374a398dccbSderaadt 
375a398dccbSderaadt int
37648bd9750Stedu exec_setup_stack(struct proc *p, struct exec_package *epp)
377a398dccbSderaadt {
378e8dad7d8Skettenis 	vsize_t dist = 0;
379a398dccbSderaadt 
380910e6419Smickey #ifdef MACHINE_STACK_GROWS_UP
38196db9035Smickey 	epp->ep_maxsaddr = USRSTACK;
38296db9035Smickey 	epp->ep_minsaddr = USRSTACK + MAXSSIZ;
383910e6419Smickey #else
3844ed6bfeaSkettenis 	epp->ep_maxsaddr = USRSTACK - MAXSSIZ - MAXSSIZ_GUARD;
385a398dccbSderaadt 	epp->ep_minsaddr = USRSTACK;
38696db9035Smickey #endif
387edc99bcdSvisa 	epp->ep_ssize = round_page(lim_cur(RLIMIT_STACK));
388a398dccbSderaadt 
389e8dad7d8Skettenis #ifdef VM_MIN_STACK_ADDRESS
390e8dad7d8Skettenis 	dist = USRSTACK - MAXSSIZ - MAXSSIZ_GUARD - VM_MIN_STACK_ADDRESS;
391e8dad7d8Skettenis 	if (dist >> PAGE_SHIFT > 0xffffffff)
392e8dad7d8Skettenis 		dist = (vsize_t)arc4random() << PAGE_SHIFT;
393e8dad7d8Skettenis 	else
394e8dad7d8Skettenis 		dist = (vsize_t)arc4random_uniform(dist >> PAGE_SHIFT) << PAGE_SHIFT;
395e8dad7d8Skettenis #else
3962bda40dcSmiod 	if (stackgap_random != 0) {
397e8dad7d8Skettenis 		dist = arc4random() & (stackgap_random - 1);
398e8dad7d8Skettenis 		dist = trunc_page(dist);
399e8dad7d8Skettenis 	}
400e8dad7d8Skettenis #endif
4012bda40dcSmiod 
402299d59e0Smiod #ifdef MACHINE_STACK_GROWS_UP
403e8dad7d8Skettenis 	epp->ep_maxsaddr += dist;
404e8dad7d8Skettenis 	epp->ep_minsaddr += dist;
405299d59e0Smiod #else
406e8dad7d8Skettenis 	epp->ep_maxsaddr -= dist;
407e8dad7d8Skettenis 	epp->ep_minsaddr -= dist;
408299d59e0Smiod #endif
4092bda40dcSmiod 
410a398dccbSderaadt 	/*
411a398dccbSderaadt 	 * set up commands for stack.  note that this takes *two*, one to
412a398dccbSderaadt 	 * map the part of the stack which we can access, and one to map
413a398dccbSderaadt 	 * the part which we can't.
414a398dccbSderaadt 	 *
415a398dccbSderaadt 	 * arguably, it could be made into one, but that would require the
416a398dccbSderaadt 	 * addition of another mapping proc, which is unnecessary
417a398dccbSderaadt 	 *
418a398dccbSderaadt 	 * note that in memory, things assumed to be: 0 ....... ep_maxsaddr
419a398dccbSderaadt 	 * <stack> ep_minsaddr
420a398dccbSderaadt 	 */
421910e6419Smickey #ifdef MACHINE_STACK_GROWS_UP
422f2e49d37Sderaadt 	NEW_VMCMD2(&epp->ep_vmcmds, vmcmd_map_zero,
42396db9035Smickey 	    ((epp->ep_minsaddr - epp->ep_ssize) - epp->ep_maxsaddr),
424f2e49d37Sderaadt 	    epp->ep_maxsaddr + epp->ep_ssize,
425f2e49d37Sderaadt 	    NULLVP, 0, PROT_NONE,  VMCMD_IMMUTABLE);
426003f5e42Sderaadt 	NEW_VMCMD2(&epp->ep_vmcmds, vmcmd_map_zero, epp->ep_ssize,
427f2e49d37Sderaadt 	    epp->ep_maxsaddr,
428f2e49d37Sderaadt 	    NULLVP, 0, PROT_READ | PROT_WRITE, VMCMD_STACK | VMCMD_IMMUTABLE);
429910e6419Smickey #else
430f2e49d37Sderaadt 	NEW_VMCMD2(&epp->ep_vmcmds, vmcmd_map_zero,
431a398dccbSderaadt 	    ((epp->ep_minsaddr - epp->ep_ssize) - epp->ep_maxsaddr),
432f2e49d37Sderaadt 	    epp->ep_maxsaddr,
433f2e49d37Sderaadt 	    NULLVP, 0, PROT_NONE, VMCMD_IMMUTABLE);
434003f5e42Sderaadt 	NEW_VMCMD2(&epp->ep_vmcmds, vmcmd_map_zero, epp->ep_ssize,
435f2e49d37Sderaadt 	    (epp->ep_minsaddr - epp->ep_ssize),
436f2e49d37Sderaadt 	    NULLVP, 0, PROT_READ | PROT_WRITE, VMCMD_STACK | VMCMD_IMMUTABLE);
437910e6419Smickey #endif
438a398dccbSderaadt 
43948bd9750Stedu 	return (0);
440a398dccbSderaadt }
441